🎙️ HTB Stories #8: Bug Bounties 101 w/InsiderPhD

🎙️ HTB Stories #8: Bug Bounties 101 w/InsiderPhD

Source: YouTube · Hack The Box · published Mar 30, 2022 · 1:00:40

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video features an AMA with Katie, a cybersecurity lecturer and bug bounty hunter, who discusses her accidental transition from software development and offers practical advice for aspiring hackers entering the industry [3:23-3:43, 5:53-6:08].

Key Takeaways:
• Katie stumbled into cybersecurity after realizing she hated her developer job; she found her first vulnerability, an IDOR, during a live hacking event in the second year of her PhD 5:53-7:26.
• She advises beginners to focus on manual testing for business logic errors and IDORs, noting that automated findings are often dominated by professionals with expensive infrastructure 13:56-14:56.
• Regarding education, Katie believes neither degrees nor certifications are strictly necessary if you possess the skills, and she cautions against incurring significant debt for credentials 29:25-30:37.
• She emphasizes that hacking is a marathon of self-improvement rather than a sprint for financial reward, suggesting that taking breaks is essential to avoid burnout 25:47-26:22.

Katie encourages a "chaotic" approach to learning, urging new hackers to start with hands-on practice immediately rather than getting lost in theoretical research [19:07-19:27, 42:05-42:10].

Sources:

  • 3:23 Introduction of Katie as a lecturer and bug bounty hunter
  • 5:53 Katie's accidental entry into cybersecurity
  • 13:56 Advice on manual testing and business logic flaws
  • 29:25 Discussion on degrees versus certifications
  • 25:47 Motivation and avoiding burnout
  • 42:05 The importance of practical experience

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Music] [Music] [Applause] [Applause] [Music] [Music] [Applause] [Music] [Music] [Music] [Music] [Music] [Music] [Applause] [Music] [Applause] [Applause] so [Music] so [Applause] [Music] [Music] so [Applause] [Music] what is going on youtube this is ipsec um normally it is saudi aka road runner who does these amas but she had a family emergency so you're stuck with me for the next like hour well actually not just me we're going to have katie akia insider phd joining us it's going to be an ama all about her and her experience and journey into cyber security it is an ama format so all these questions come sourced from discord twitter other places and we'll be picking prizes at the end of this along with picking extra questions once we run through all the ones we want um a little bit about ha…